Memory leak in client induced by malicious server without CURVE/ZAP (rhbz#1921972). Stack overflow on server running PUB/XPUB socket (rhbz#1921976). . MGASA-2021-0159 - Updated zeromq packages fix security vulnerabilities Publication date: 30 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0159.html Type: security Affected Mageia releases: 7, 8 Memory leak in client induced by malicious server without CURVE/ZAP (rhbz#1921972). Stack overflow on server running PUB/XPUB socket (rhbz#1921976). Heap overflow when receiving malformed ZMTP v1 packets (rhbz#1921983). Memory leaks via metadata messages processed by PUB sockets (rhbz#1921989). Also, the cppzmq package has been rebuilt to fix the broken dependency on zeromq-devel. References: - https://bugs.mageia.org/show_bug.cgi?id=28320 - https://lists.zeromq.org/pipermail/zeromq-announce/2021-January/000068.html - https://lists.fedoraproject.org/archives/list/
- Upstream upgrade - Fixes #1921879, #1921972, #1921973, #1921975, #1921976, #1921979, #1921981, #1921983, #1921983, #1921985, #1921987, #1921989, #1921992, #1921994. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8b3202b783 2021-02-08 01:29:15.824785 --------------------------------------------------------------------------------Name : zeromq Product : Fedora 33 Version : 4.3.4 Release : 1.fc33 URL : https://zeromq.org Summary : Software library for fast, message-based applications Description : The 0MQ lightweight messaging kernel is a library which extends the standard socket interfaces with features traditionally provided by specialized messaging middle-ware products. 0MQ sockets provide an abstraction of asynchronous message queues, multiple messaging patterns, message filtering (subscriptions), seamless access to multiple transport protocols and more. This package contains the ZeroMQ shared library. --------------------------------------------------------------------------------Update Information: - Upstream upgrade - Fixes #1921879, #1921972, #1921973, #1921975, #1921976, #1921979, #1921981, #1921983, #1921983, #1921985, #1921987, #1921989, #1921992, #1921994 --------------------------------------------------------------------------------ChangeLog: * Sat Jan 30 2021 Denis Arnaud - 4.3.4-1 - Upstream upgrade - Fixes #1921879, #1921972, #1921973, #1921975, #1921976, #1921979, #1921981, - #1921983, #1921983, #1921985, #1921987, #1921989, #1921992, #1921994 --------------------------------------------------------------------------------References: [ 1 ] Bug #1921972 - zeromq: Memory leak in client induced by malicious server without CURVE/ZAP https://bugzilla.redhat.com/show_bug.cgi?id=1921972 [ 2 ] Bug #1921976 - zeromq: Stack overflow on server running PUB/XPUB socket https://bugzilla.redhat.com/show_bug.cgi?id=1921976 [ 3 ] Bug #1921983 -zeromq: Heap overflow when receiving malformed ZMTP v1 packets https://bugzilla.redhat.com/show_bug.cgi?id=1921983 [ 4 ] Bug #1921989 - zeromq: Memory leaks via metadata messages processed by PUB sockets https://bugzilla.redhat.com/show_bug.cgi?id=1921989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8b3202b783' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that solves one vulnerability and has four fixes is now available. . openSUSE Security Update: Security update for zeromq ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1910-1 Rating: moderate References: #1176116 #1176256 #1176257 #1176258 #1176259 Cross-References: CVE-2020-15166 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has four fixes is now available. Description: This update for zeromq fixes the following issues: - CVE-2020-15166: Fixed the possibility of unauthenticated clients causing a denial-of-service (bsc#1176116). - Fixed a heap overflow when receiving malformed ZMTP v1 packets (bsc#1176256) - Fixed a memory leak in client induced by malicious server(s) without CURVE/ZAP (bsc#1176257) - Fixed memory leak when processing PUB messages with metadata (bsc#1176259) - Fixed a stack overflow in PUB/XPUB subscription store (bsc#1176258) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1910=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libunwind-1.2.1-lp152.5.3.1 libunwind-debuginfo-1.2.1-lp152.5.3.1 libunwind-debugsource-1.2.1-lp152.5.3.1 libunwind-devel-1.2.1-lp152.5.3.1 - openSUSE Leap 15.2 (x86_64): libunwind-32bit-1.2.1-lp152.5.3.1 libunwind-32bit-debuginfo-1.2.1-lp152.5.3.1 libzmq5-4.2.3-lp152.7.3.1 libzmq5-debuginfo-4.2.3-lp152.7.3.1 zeromq-debugsource-4.2.3-lp152.7.3.1 zeromq-devel-4.2.3-lp152.7.3.1 zeromq-tools-4.2.3-lp152.7.3.1 zeromq-tools-debuginfo-4.2.3-lp152.7.3.1 References: https://www.suse.com/security/cve/CVE-2020-15166.html https://bugzilla.suse.com/1176116 https://bugzilla.suse.com/1176256 https://bugzilla.suse.com/1176257 https://bugzilla.suse.com/1176258 https://bugzilla.suse.com/1176259 _______________________________________________ openSUSE Security Announce mailing list --
An update that solves one vulnerability and has four fixes is now available. . openSUSE Security Update: Security update for zeromq ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1907-1 Rating: moderate References: #1176116 #1176256 #1176257 #1176258 #1176259 Cross-References: CVE-2020-15166 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves one vulnerability and has four fixes is now available. Description: This update for zeromq fixes the following issues: - CVE-2020-15166: Fixed the possibility of unauthenticated clients causing a denial-of-service (bsc#1176116). - Fixed a heap overflow when receiving malformed ZMTP v1 packets (bsc#1176256) - Fixed a memory leak in client induced by malicious server(s) without CURVE/ZAP (bsc#1176257) - Fixed memory leak when processing PUB messages with metadata (bsc#1176259) - Fixed a stack overflow in PUB/XPUB subscription store (bsc#1176258) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1907=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libunwind-1.2.1-lp151.4.3.1 libunwind-debuginfo-1.2.1-lp151.4.3.1 libunwind-debugsource-1.2.1-lp151.4.3.1 libunwind-devel-1.2.1-lp151.4.3.1 - openSUSE Leap 15.1 (x86_64): libunwind-32bit-1.2.1-lp151.4.3.1 libunwind-32bit-debuginfo-1.2.1-lp151.4.3.1 libzmq5-4.2.3-lp151.5.6.1 libzmq5-debuginfo-4.2.3-lp151.5.6.1 zeromq-debugsource-4.2.3-lp151.5.6.1 zeromq-devel-4.2.3-lp151.5.6.1 zeromq-tools-4.2.3-lp151.5.6.1 zeromq-tools-debuginfo-4.2.3-lp151.5.6.1 References: https://www.suse.com/security/cve/CVE-2020-15166.html https://bugzilla.suse.com/1176116 https://bugzilla.suse.com/1176256 https://bugzilla.suse.com/1176257 https://bugzilla.suse.com/1176258 https://bugzilla.suse.com/1176259 _______________________________________________ openSUSE Security Announce mailing list --
It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2443-1
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for zeromq ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3064-1 Rating: moderate References: #1176257 #1176258 Affected Products: SUSE Manager Tools 12 SUSE Manager Server 3.2 SUSE Manager Proxy 3.2 SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Point of Sale 12-SP2 SUSE Linux Enterprise Module for Advanced Systems Management 12 SUSE Enterprise Storage 5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for zeromq fixes the following issues: - Fixed a memory leak in client induced by malicious server(s) without CURVE/ZAP (bsc#1176257) - Fixed a stack overflow in PUB/XPUB subscription store (bsc#1176258) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Tools 12: zypper in -t patch SUSE-SLE-Manager-Tools-12-2020-3064=1 - SUSE Manager Server 3.2: zypper in -t patch SUSE-SUSE-Manager-Server-3.2-2020-3064=1 - SUSE Manager Proxy 3.2: zypper in -t patch SUSE-SUSE-Manager-Proxy-3.2-2020-3064=1 - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-3064=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-3064=1 - SUSE Linux Enterprise Point of Sale 12-SP2: zypper in -t patch SUSE-SLE-POS-12-SP2-2020-3064=1 - SUSELinux Enterprise Module for Advanced Systems Management 12: zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2020-3064=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-3064=1 Package List: - SUSE Manager Tools 12 (aarch64 ppc64le s390x x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Manager Server 3.2 (ppc64le s390x x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Manager Proxy 3.2 (x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 zeromq-devel-4.0.4-15.6.1 - SUSE Linux Enterprise Point of Sale 12-SP2 (x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Linux Enterprise Module for Advanced Systems Management 12 (ppc64le s390x x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): libzmq3-4.0.4-15.6.1 libzmq3-debuginfo-4.0.4-15.6.1 zeromq-debugsource-4.0.4-15.6.1 References: https://bugzilla.suse.com/1176257 https://bugzilla.suse.com/1176258 . Security update for zeromq addresses memory leak and stack overflow vulnerabilities affecting SUSE systems.. zeromq update, SUSE security, memory leak, stack overflow, security fix. . LinuxSecurity.com Team
The package zeromq before version 4.3.3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-202009-16 ========================================= Severity: High Date : 2020-09-26 CVE-ID : CVE-2020-15166 Package : zeromq Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-1219 Summary ====== The package zeromq before version 4.3.3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 4.3.3-1. # pacman -Syu "zeromq> =4.3.3-1" The problem has been fixed upstream in version 4.3.3. Workaround ========= None. Description ========== A denial of service has been found in libzmq before 4.3.3, allowing unauthenticated clients to prevent legitimate clients from exchange any message with a CURVE/ZAP-protected server. Impact ===== A remote attacker might be able to cause a denial of service through a malicious connection. References ========= https://github.com/zeromq/libzmq/security/advisories/GHSA-25wp-cf8g-938m https://github.com/zeromq/libzmq/pull/3913/commits/e7f0090b161ce6344f6bd35009816a925c070b09 https://oss-fuzz.com/login https://security.archlinux.org/CVE-2020-15166 . The Arch Linux Security Advisory ASA-202009-16 discusses a denial of service vulnerability in zeromq, outlining its potential impacts and suggested mitigation strategies. zeromq Denial Of Service Arch Linux Security Advisory Upgrade. . LinuxSecurity.com Team
Fix of #1876738 and #1876689. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-5460fcf6bd 2020-09-25 16:31:57.897781 --------------------------------------------------------------------------------Name : zeromq Product : Fedora 33 Version : 4.3.3 Release : 1.fc33 URL : https://zeromq.org Summary : Software library for fast, message-based applications Description : The 0MQ lightweight messaging kernel is a library which extends the standard socket interfaces with features traditionally provided by specialized messaging middle-ware products. 0MQ sockets provide an abstraction of asynchronous message queues, multiple messaging patterns, message filtering (subscriptions), seamless access to multiple transport protocols and more. This package contains the ZeroMQ shared library. --------------------------------------------------------------------------------Update Information: Fix of #1876738 and #1876689 --------------------------------------------------------------------------------ChangeLog: * Tue Sep 15 2020 Denis Arnaud - 4.3.3-1 - Upstream upgrade - Fixes #1876738 and #1876689 --------------------------------------------------------------------------------References: [ 1 ] Bug #1876689 - CVE-2020-15166 zeromq: unauthenticated clients causing denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1876689 [ 2 ] Bug #1876738 - zeromq-4.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1876738 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-5460fcf6bd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.